.NET 8 macOS应用App Store审核时出现开发者验证错误
.NET 8 macOS应用App Store审核遇Gatekeeper验证失败问题
问题现象
- App Store审核反馈:应用启动出错,提示「无法打开应用,因为无法验证开发者,这可能与应用的Gatekeeper合规性问题有关」
- 审核截图显示:「应用已损坏,无法打开,请从App Store删除并重新安装」
- TestFlight安装后无此问题
打包流程
- 构建应用:
dotnet build {SolutionFileName} --configuration Release - 签名应用:
codesign --force --verify --verbose --deep --options runtime --timestamp --entitlements ../Entitlements.plist -s '3rd Party Mac Developer Application: [ID]' Demo.app - 创建安装包:
productbuild --component Demo.app /Applications --sign '3rd Party Mac Developer Installer: [ID]' Demo.pkg
Entitlements.plist配置
<key>com.apple.application-identifier</key> <string>[ID].com.demo.appc</string> <key>com.apple.developer.team-identifier</key> <string>[ID]</string> <key>com.apple.security.app-sandbox</key> <true/> <key>com.apple.security.files.user-selected.read-write</key> <true/> <key>com.apple.security.network.client</key> <true/> <key>com.apple.security.files.bookmarks.app-scope</key> <true/> <key>com.apple.security.cs.allow-jit</key> <true/> <key>com.apple.security.cs.allow-unsigned-executable-memory</key> <true/> <key>com.apple.security.cs.allow-dyld-environment-variables</key> <true/> <key>com.apple.security.cs.disable-library-validation</key> <true/>
项目发布配置片段
<PropertyGroup Condition=" '$(Configuration)|$(Platform)' == 'Release|AnyCPU' "> <OutputPath>bin\Release</OutputPath> <Optimize>true</Optimize> <NoStdLib>true</NoStdLib> <UseSGen>false</UseSGen> <UseRefCounting>false</UseRefCounting> <TlsProvider>Default</TlsProvider> <PublishTrimmed>true</PublishTrimmed> <TrimMode>partial</TrimMode> <RunAOTCompilation>false</RunAOTCompilation> <EnablePackageSigning>true</EnablePackageSigning> <CodeSigningKey>3rd Party Mac Developer Application:[ID]</CodeSigningKey> <EnableCodeSigning>True</EnableCodeSigning> <CreatePackage>false</CreatePackage> <PackageSigningKey>3rd Party Mac Developer Installer:[ID]</PackageSigningKey> <Profiling>false</Profiling> <CodeSignProvision>provfile</CodeSignProvision> <CodeSignEntitlements>Entitlements.plist</CodeSignEntitlements> <LangVersion>default</LangVersion> </PropertyGroup>
证书状态
执行security find-identity -vp macappstore输出:
5) "3rd Party Mac Developer Application: [ID]" (Missing required extension) 6) "3rd Party Mac Developer Installer: [ID]" (Missing required extension)
问题分析与解决方案
1. 修复证书缺失扩展问题
证书提示「Missing required extension」是核心原因,直接导致Gatekeeper无法验证签名:
- 登录Apple开发者后台,删除现有Mac开发/安装证书,重新生成对应Mac App Store分发的证书(确保证书类型选择正确,不要选成开发用证书)
- 下载新证书导入Keychain后,重新执行
security find-identity -vp macappstore,确认不再显示「Missing required extension」
2. 优化签名流程
- 关闭项目文件中的
<EnableCodeSigning>True</EnableCodeSigning>和<EnablePackageSigning>true</EnablePackageSigning>,避免dotnet自动签名与手动签名冲突 - 签名时移除
--deep参数,.NET应用无需深度签名,改为仅签名主App包:codesign --force --verify --verbose --options runtime --timestamp --entitlements ../Entitlements.plist -s '3rd Party Mac Developer Application: [ID]' Demo.app - 用
codesign --verify --verbose=4 Demo.app检查签名完整性,确保所有嵌套组件签名有效
3. 调整构建命令
替换dotnet build为dotnet publish,确保打包所有依赖项:
dotnet publish {ProjectFileName} --configuration Release --runtime osx-x64 --self-contained false
(根据你的硬件架构调整runtime参数,如osx-arm64)
4. 验证权限配置
- 确认
com.apple.application-identifier格式为TeamID.BundleID,与开发者后台的App ID完全一致 - 确保
com.apple.developer.team-identifier值与证书中的TeamID一致,无拼写错误
5. 本地验证安装包
重新打包后,先本地验证合规性:
- 用altool验证安装包:
xcrun altool --validate-app -f Demo.pkg -t osx -u "你的Apple ID" -p "应用专用密码" - 安装后检查Gatekeeper状态:
需输出spctl --assess --verbose Demo.appaccepted才符合要求
内容的提问来源于stack exchange,提问作者jaroslavic
相关产品推荐
相关产品推荐

